Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-0261

Опубликовано: 16 янв. 2007
Источник: nvd
CVSS2: 10
EPSS Низкий

Описание

snews.php in sNews 1.5.30 and earlier does not properly exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, as demonstrated by changing an administrative password via the changeup task, and by uploading PHP code via the imagefile parameter.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:snews:snews:1.5.29:*:*:*:*:*:*:*
cpe:2.3:a:snews:snews:1.5.30:*:*:*:*:*:*:*

EPSS

Процентиль: 93%
0.0979
Низкий

10 Critical

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
больше 3 лет назад

snews.php in sNews 1.5.30 and earlier does not properly exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, as demonstrated by changing an administrative password via the changeup task, and by uploading PHP code via the imagefile parameter.

EPSS

Процентиль: 93%
0.0979
Низкий

10 Critical

CVSS2

Дефекты

NVD-CWE-Other